<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Installing a new cert in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/installing-a-new-cert/m-p/475029#M103415</link>
    <description>&lt;P&gt;For Global Protect I currently have a server cert on my PAN 3220. When i imported it it had the entire chain - root, intermediate and the server cert. That server cert is now nearing expiration. I gave our cert manager a CSR from the PAN and I now have the new .PEM formatted server cert with longer expiry and the chain which includes the root and intermediate certs.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) Can I install this into the device certificates store under a different certificate name? And this would not affect the existing certificate profile.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) To upgrade to the new cert my plan would be to change the certificate profiles to point to the new server cert and then test that Global Protect is authenticating OK. If the cert based auth GP was failing then I would change back the cert profile to point to the old certificate. Does this sounds like a reasonable approach?&lt;/P&gt;</description>
    <pubDate>Tue, 22 Mar 2022 19:06:35 GMT</pubDate>
    <dc:creator>palomed</dc:creator>
    <dc:date>2022-03-22T19:06:35Z</dc:date>
    <item>
      <title>Installing a new cert</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/installing-a-new-cert/m-p/475029#M103415</link>
      <description>&lt;P&gt;For Global Protect I currently have a server cert on my PAN 3220. When i imported it it had the entire chain - root, intermediate and the server cert. That server cert is now nearing expiration. I gave our cert manager a CSR from the PAN and I now have the new .PEM formatted server cert with longer expiry and the chain which includes the root and intermediate certs.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) Can I install this into the device certificates store under a different certificate name? And this would not affect the existing certificate profile.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) To upgrade to the new cert my plan would be to change the certificate profiles to point to the new server cert and then test that Global Protect is authenticating OK. If the cert based auth GP was failing then I would change back the cert profile to point to the old certificate. Does this sounds like a reasonable approach?&lt;/P&gt;</description>
      <pubDate>Tue, 22 Mar 2022 19:06:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/installing-a-new-cert/m-p/475029#M103415</guid>
      <dc:creator>palomed</dc:creator>
      <dc:date>2022-03-22T19:06:35Z</dc:date>
    </item>
    <item>
      <title>Re: Installing a new cert</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/installing-a-new-cert/m-p/475050#M103420</link>
      <description>&lt;P&gt;If you try to upload a cert that is a renewal of an identical cert - the fw will likely just replace the existing one with the new one. The name you give it on the fw will not matter. The fw will see the body of the certificate is identical to one already installed that just has an extended expiration date, and update the existing cert with the new name you gave it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm certainly no certificate expert. But I've had the best luck using the shotgun method. Delete the existing cert chain then upload the updated cert chain.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Mar 2022 20:22:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/installing-a-new-cert/m-p/475050#M103420</guid>
      <dc:creator>addawes</dc:creator>
      <dc:date>2022-03-22T20:22:21Z</dc:date>
    </item>
  </channel>
</rss>

